US2024214183A1PendingUtilityA1

Authority management method

Assignee: ZHUHAI PANTUM ELECTRONICS CO LTDPriority: Dec 21, 2022Filed: Dec 12, 2023Published: Jun 27, 2024
Est. expiryDec 21, 2042(~16.4 yrs left)· nominal 20-yr term from priority
Inventors:Wei-Jhih Lian
H04L 9/3213H04L 9/0825H04L 63/0807
48
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

An authority management method. The method is applied to a first terminal device, and includes: sending a first authority application request to an authority management device, the first authority application request being configured to apply for a first authority, the first authority being an authority that is desired to be obtained by the first terminal device, and the first authority being a task authority for an execution device; and receiving a first authorization information block sent by the authority management device, the first authorization information block including first authorization information encrypted by a first private key, the first authorization information including description information for the first authority, the first private key being a key matching a first public key, and the first public key is stored in the execution device.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . An authority management method, comprising:
 a first terminal device sending a first authority application request to an authority management device, receiving a first authorization information block sent by the authority management device, wherein the first authorization information block comprises first authorization information encrypted by a first private key;   an authority management device receiving a first authority application request sent by a first terminal device, generating first authorization information based on the first authority application request, encrypting the first authorization information using a first private key to generate a first authorization information block, sending the first authorization information block to the first terminal device;   wherein the first authority application request is used to apply for a first authority, the first authority is an authority that is desired to be obtained by the first terminal device, and the first authority is a task authority for an execution device; the first authorization information comprises description information for the first authority, the first private key is a key matching a first public key, and the first public key is stored in the execution device.   
     
     
         2 . The method according to  claim 1 , further comprising:
 sending the first authorization information block to the execution device when a task needs to be sent to the execution device.   
     
     
         3 . The method according to  claim 1 ,
 wherein the first authority application request comprises a second public key, the second public key is a key matching a second private key, and the second public key and the second private key are stored in the first terminal device;   wherein the first authority application request is further configured to apply for a second authority, the second authority is an authority that allows the first terminal device to authorize another terminal device, and the second authority is a task authority for the execution device; and   wherein the first authorization information further comprises description information for the second authority, and the second public key.   
     
     
         4 . The method according to  claim 3 , further comprising:
 receiving a second authority application request sent by a second terminal device, wherein the second authority application request is configured to apply for a third authority, the third authority is an authority that is desired to be obtained by the second terminal device, and the third authority is a task authority for the execution device;   generating second authorization information based on the second authority application request, wherein the second authorization information comprises description information for the third authority;   encrypting the second authorization information using the second private key to generate a second authorization information block;   generating a first authorization information chain, wherein the first authorization information chain comprises the first authorization information block and the second authorization information block; and   sending the first authorization information chain to the second terminal device.   
     
     
         5 . The method according to  claim 4 , wherein the second authority application request comprises a third public key, the third public key is a key matching a third private key, and the third public key and the third private key are stored in the second terminal device;
 the second authority application request is further configured to apply for a fourth authority, the fourth authority is an authority that allows the second terminal device to authorize another terminal device, and the fourth authority is a task authority for the execution device; and   during said generating second authorization information based on the second authority application request, the second authorization information further comprises description information for the fourth authority, and the third public key.   
     
     
         6 . The method according to  claim 1 , wherein the first authorization information comprises one or a combination of an authorizer identity, an authorized-object identity, an authorization moment, an authorization period, an authority range, and a consumable share. 
     
     
         7 . The method according to  claim 1 , wherein the first authorization information comprises a subsidiary token information summary of a subsidiary token bound with the first authorization information; and
 the method further comprises: receiving the subsidiary token sent by the authority management device; generating the subsidiary token; and   sending the subsidiary token to the first terminal device.   
     
     
         8 . An authority management method, applied to a second terminal device and comprising:
 sending a second authority application request to a first terminal device, wherein the second authority application request is configured to apply for a third authority, the third authority is an authority that is desired to be obtained by the second terminal device, and the third authority is a task authority for an execution device; and   receiving a first authorization information chain sent by the first terminal device, wherein the first authorization information chain comprises authorization information blocks;   wherein a first one authorization information block of the authorization information blocks of the first authorization information chain comprises first authorization information encrypted by a first private key, the first private key is a key matching a first public key, and the first public key is stored in the execution device;   each authorization information block of the first authorization information chain comprises authorization information encrypted by a private key;   the authorization information of each authorization information block of the first authorization information chain comprises a public key matching the private key configured to encrypt the authorization information in a next one authorization information block; and   the authorization information of a last one authorization information block of the authorization information blocks of the first authorization information chain comprises description information for the third authority.   
     
     
         9 . The method according to  claim 8 , further comprising:
 sending the first authorization information chain to the execution device when a task needs to be sent to the execution device.   
     
     
         10 . The method according to  claim 8 , wherein the second authority application request comprises a third public key, the third public key is a key matching a third private key, and the third public key and the third private key are stored in the second terminal device;
 the second authority application request is further configured to apply for a fourth authority, the fourth authority is an authority that allows the second terminal device to authorize another terminal device, and the fourth authority is a task authority for the execution device; and   the authorization information of the last one authorization information block of the authorization information blocks of the first authorization information chain further comprises description information for the fourth authority, and the third public key.   
     
     
         11 . The method according to  claim 10 , further comprising:
 receiving a third authority application request sent by a third terminal device, wherein the third authority application request is configured to apply for a fifth authority, the fifth authority is an authority that is desired to be obtained by the third terminal device, and the fifth authority is a task authority for the execution device;   generating third authorization information based on the third authority application request, wherein the third authorization information comprises description information for the fifth authority;   encrypting the third authorization information using the third private key to generate a third authorization information block;   adding the third authorization information block to a tail of the first authorization information chain to generate a second authorization information chain; and   sending the second authorization information chain to the third terminal device.   
     
     
         12 . The method according to  claim 8 , wherein authorization information of each authorization information block of the first authorization information chain comprises one or a combination of an authorizer identity, an authorized-object identity, an authorization moment, an authorization period, an authority range, and a consumable share. 
     
     
         13 . The method according to  claim 8 , wherein the first authorization information comprises a subsidiary token information summary of a subsidiary token bound with the first authorization information; and
 the method further comprises: receiving the subsidiary token sent by the first terminal device.   
     
     
         14 . An authority management method, applied to an execution device and comprising:
 receiving a first authorization information block sent by a terminal device, wherein the first authorization information block comprises first authorization information encrypted by a first private key, the first private key is a key matching a first public key, and the first public key is stored in the execution device; and   decrypting the first authorization information block using the first public key to obtain the first authorization information.   
     
     
         15 . The method according to  claim 14 , wherein the first authorization information block is generated by an authority management device based on an authority application request of the terminal device. 
     
     
         16 . The method according to  claim 14 , further comprising:
 verifying legality of the first authorization information;   obtaining authority information of the terminal device based on the first authorization information in response to verification success of the first authorization information; and   determining whether to execute a task issued by the terminal device based on the authority information of the terminal device.   
     
     
         17 . The method according to  claim 14 , wherein said receiving a first authorization information block sent by a terminal device comprises: receiving an authorization information chain sent by the terminal device, wherein the authorization information chain comprises authorization information blocks encrypted by different private keys, a first one authorization information block of the authorization information blocks of the authorization information chain is the first authorization information block, and the authorization information of each authorization information block of the authorization information chain comprises a public key matching a private key configured to encrypt the authorization information in a next one authorization information block; and
 the method further comprises:   obtaining a public key matching the next one authorization information block from the authorization information of each decrypted authorization information block to decrypt the next one authorization information block, and obtaining the authorization information of the next one authorization information block, wherein the public key matching a second authorization information block is obtained from the first authorization information to decrypt the second authorization information block, to obtain the authorization information of the second authorization information block;   verifying legality of the authorization information of a last one authorization information block of the authorization information blocks of the authorization information chain;   obtaining authority information of the terminal device based on the authorization information of the last one authorization information block of the authorization information blocks in response to verification success of the authorization information of the last one authorization information block of the authorization information blocks; and   determining whether to execute a task issued by the terminal device based on the authority information of the terminal device.   
     
     
         18 . The method according to  claim 14 , wherein the first authorization information comprises one or a combination of an authorizer identity, an authorized-object identity, an authorization moment, an authorization period, an authority range, and a consumable share. 
     
     
         19 . The method according to  claim 14 , wherein the first authorization information comprises a subsidiary token information summary of a subsidiary token bound with the first authorization information; and
 the method further comprises: receiving the subsidiary token sent by the terminal device, and verifying whether the subsidiary token matches the first authorization information.

Join the waitlist — get patent alerts

Track US2024214183A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.